TLS Guide

How to Check an SSL/TLS Certificate Online

Checking a live TLS endpoint helps verify that its certificate is trusted, valid for the requested hostname, not expired, and deployed with an appropriate TLS configuration.

Open SSL/TLS Checker →

What is an SSL/TLS certificate?

TLS certificates establish the identity of HTTPS services and provide the public-key information needed to establish an encrypted connection.

The term SSL certificate is still commonly used, although modern HTTPS connections use TLS rather than the obsolete SSL protocols.

How to check an SSL certificate online

  1. 1. Enter the domain name or HTTPS hostname.
  2. 2. Use port 443 unless the service uses another TLS port.
  3. 3. Open the SSL/TLS Checker.
  4. 4. Run the TLS check.
  5. 5. Review trust status, validity, protocol, cipher, certificate chain, and security findings.

What should you check?

Certificate trust

A valid certificate should chain to a trusted Certificate Authority and pass certificate verification.

Hostname

The requested hostname should be present in the certificate Subject Alternative Name extension.

Expiration

Check the Not After value and ensure the certificate will not expire unexpectedly.

TLS protocol

Modern deployments should generally negotiate TLS 1.2 or TLS 1.3 rather than obsolete SSL or old TLS versions.

Cipher suite

The negotiated cipher suite determines the cryptographic algorithms used for the connection.

Certificate chain

A server normally presents its leaf certificate and the intermediate certificates needed to establish trust.

HSTS

HTTP Strict Transport Security tells compatible browsers to access the site using HTTPS.

SSL certificate checker vs. certificate decoder

A live SSL/TLS checker connects to the server and examines its deployed TLS configuration.

If you already have a PEM certificate and only want to inspect its contents, use the X.509 Certificate Decoder instead.

Can you check TLS with OpenSSL?

Yes. A common command for connecting to a TLS server is:

openssl s_client -connect example.com:443 -servername example.com

This is useful for command-line troubleshooting. A browser checker can provide the same workflow in a more structured format.

Related tools

Check an SSL/TLS certificate now

Inspect the certificate and TLS configuration exposed by a public HTTPS endpoint.

Open SSL/TLS Checker →